Impact
The vulnerability in the Graph / Charting component of Oracle Applications Framework is an instance of CWE‑284: Improper Access Control. It allows a low‑privileged attacker who can reach the HTTP interface to bypass normal authorization checks, enabling unauthorized creation, deletion or alteration of critical data. The flaw results in loss of confidentiality and integrity for all data exposed through the framework, potentially exposing sensitive business information to manipulation.
Affected Systems
Oracle Corporation’s Oracle Applications Framework product, specifically the Graph / Charting component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 classifies this as high severity. The attack vector is network‑based, with a low attack complexity and low privilege requirement, and the EPSS score of less than 1% indicates that malicious exploitation is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. However, a low‑privileged network attacker can compromise data confidentiality and integrity across the framework if a patch or workaround is not applied.
OpenCVE Enrichment